July 2, 2026
SOC 1 vs SOC 2: Which Report Does Your Company Need?SOC 1 covers financial reporting controls; SOC 2 covers security and trust. A Colorado CPA firm explains which report your clients are…
Read more →Licensed CPA Firm
Independent SOC 2 examinations for cloud providers, SaaS companies, and IT service organizations.
SOC 2 is a framework used to show your customers how you protect their data. We conduct SOC 2 engagements under AICPA standards, independently testing your controls against the Trust Services Criteria and issuing an opinion your customers and their security teams can rely on. If you want the examination itself unpacked first, our SOC 2 compliance audit page covers what gets tested and who is allowed to test it.
Independent assessment of your controls against the AICPA Trust Services Criteria, covering how your organization addresses security, availability, and other categories relevant to your customers.
Verified by a licensed CPA firm under AICPA SSAE standards, not a self-assessment or platform-generated badge.
Close deals faster by giving enterprise buyers the independent evidence they require before signing contracts.
A SOC 2 Report removes a major procurement barrier and signals operational maturity to partners and prospects.

Licensed AICPA CPA Firm
Authorized to issue SOC 2 Reports under AICPA SSAE No. 18 and subsequent standards
No two environments are the same, and no two SOC Reports should be either. We write reports designed to hold up under scrutiny, because your customers' security teams will read them.
Connect with an ExpertNot sure if you need a SOC 2 Report?
Try our two minute quiz
Independence is what makes a report worth reading, so we test your controls and form our own opinion. Every environment is built differently, and knowing your stack means yours reads that way. Nothing in the Report we have not already discussed.
Good questions come from actually knowing the technology. We have built and managed real IT environments, so you spend less time explaining your architecture and more time getting through the audit.
The partner runs your audit, not a junior associate you have never met. The team is small and US based. We provide fast, informed turnarounds.
We work on your calendar and target a draft report within two weeks of fieldwork. Use a compliance platform? We pull evidence from where it lives. If we are not the right fit, we will tell you that too.
Trust Services Criteria
SOC 2 engagements assess your controls across the AICPA Trust Services Criteria. Security is required; additional categories are selected based on your commitments to customers.
Security (Required)
Controls protecting against unauthorized access, both logical and physical. The foundation of every SOC 2 engagement.
Availability, Integrity, Confidentiality & Privacy
Additional criteria selected based on your service commitments. We help you determine which apply to your environment and customer expectations.
Which Report, and When?
Very few companies jump straight to the report their buyers want. SOC 2 is a sequence of stops, each one feeding the next, and the right place to start depends on how mature your controls are today. Handed a request for a SOC 1 instead? Our SOC 1 vs SOC 2 guide untangles which report your customer actually means.
Starting Point
4 to 8 weeks
Scout the route before the meter is running. We measure what you already have in place against the Trust Services Criteria and leave you a prioritized gap list to close on your own schedule, with no opinion issued and nothing reportable hanging over the work.
Best if you have never been through a SOC 2, or you suspect a few of your controls exist more on paper than in practice.
Start with readiness →First Milestone
1 to 2 months
A point-in-time opinion covering whether your controls are suitably designed as of a single date. No other report gets a CPA's signature in front of a buyer sooner.
Best if a security questionnaire is holding up a signature and a Type II observation window has not had time to run.
Compare Type I and Type II →The Destination
Typically 6 to 12 months
Evidence that your controls operated across an observation window, not just that they existed on one good day. A first window can be as short as 3 months. This is the report enterprise buyers ultimately require, renewed annually.
Best if enterprise buyers sit in your pipeline; their vendor-risk teams rarely accept anything less.
How we run the examination →The map does not end at Type II
Renewal is annual, which turns the audit into a standing relationship rather than a transaction. Expect three things from us between report cycles: a partner who answers year-round, not only during fieldwork; early word when the AICPA updates SOC 2 guidance; and, once your Type II is issued, the option of a SOC 3 companion report you can share publicly with no NDA.
Side by Side
The two reports differ on six practical dimensions: what the auditor opines on, when the evidence comes from, how deep the testing goes, what your customers will accept, what the engagement costs, and how quickly you have a report in hand.
| Dimension | SOC 2 Type 1 | SOC 2 Type 2 |
|---|---|---|
| What the auditor opines on | Suitability of control design as of a specific date | Control design plus operating effectiveness across the full period |
| Timing | Point-in-time snapshot | Observation period, typically 6 to 12 months; a first period can be as short as 3 months |
| Evidence depth | Walkthroughs and a single instance of each control | Samples pulled from the entire period for each control |
| What customers accept | Early proof, often paired with a commitment to deliver a Type 2 | The report most enterprise security teams expect for ongoing relationships |
| Relative cost | Lower, since testing is limited to design | Higher, since every control is tested across the observation period |
| Time to a report in hand | Weeks | Months, driven by the length of the observation period |
Because a Type 2 requires sampling evidence from every part of the period, it involves substantially more testing than a Type 1. That is why it costs more, and why it carries more weight with the people reading it. Both engagement types are quoted as fixed fees at Sage Audits; our pricing page explains how we scope them.
What to Expect
Every engagement is partner-led and fixed-fee. Here is what the journey looks like, from first call to report in your hands.
Week 1-2
We discuss your services, systems, control objectives, subservice organizations, and target report date. You receive a detailed engagement plan and request list.
1 to 6 months, with remediation
For first-time engagements: we identify control gaps, map controls to the Trust Services Criteria, and deliver a prioritized remediation roadmap before your audit period begins.
Concentrated 3 to 4 week window
Evidence collection, control testing, and interviews, concentrated late in the audit period. We schedule around your operational peaks and work directly with control owners throughout.
Draft ~2 weeks after fieldwork
You receive a polished draft reviewed for consistency, accuracy, and clarity, with the final report issued within 5 to 7 weeks of period end. We debrief on findings and coordinate with your clients' auditors as needed.
Year-round
We stay involved after report delivery, helping with auditor questions, control updates, and keeping you ready for the next audit cycle.
GRC Platform Compatible
Already using a compliance automation platform? We work with your existing stack, collecting evidence from your tools and making the most of what is already there. Bring your platform. Our approach follows AICPA guidance on the use of software tools in SOC 2 examinations.
Our Services
Whether you're preparing for your first SOC 2 or renewing an existing report, we work directly with your team through every phase. No handoffs to junior staff, no surprises at the finish line. Learn more about our firm
Maps your controls to the Trust Services Criteria and identifies documentation gaps before your audit period starts.
The right starting point for organizations pursuing their first SOC 2 or returning after significant environment changes. Surfaces gaps, clarifies scope, and delivers a prioritized remediation roadmap before the clock starts.
As part of this assessment, we will:
Point-in-time assessment of control design. A practical first step if you need a report quickly while building toward Type II.
Evaluates whether your controls are suitably designed to meet the Trust Services Criteria as of a specific date. Provides an independent CPA opinion on your control environment and can satisfy customer requests while you prepare for a full Type II.
The Type I report includes:
Tests control design and operating effectiveness over an audit period of typically 6 to 12 months. Required by most enterprise customers.
The standard most enterprise buyers and security teams require. Assesses both the design and operating effectiveness over an audit period, providing the most comprehensive independent assurance that your controls work consistently over time.
Each Type II report includes:
Map your SOC 2 controls to additional compliance frameworks within a single engagement, reducing duplication and maximizing your audit investment.
Frameworks we currently map alongside SOC 2:
How It Works
Every engagement follows a structured, phased approach. You always know where things stand, what is next, and what is expected.
See Full Process DetailsScoping & Planning
Week 1-2
We discuss your services, systems, control objectives, subservice organizations, and target report date. You receive a detailed engagement plan and request list.
Readiness Assessment Optional
1 to 6 months, with remediation
For first-time engagements: we identify control gaps, map controls to objectives, and deliver a prioritized remediation roadmap before your audit period begins.
Fieldwork & Testing
Concentrated 3 to 4 week window
Evidence collection, control testing, and interviews, concentrated late in the audit period. We schedule around your operational peaks and work directly with control owners throughout.
Report Delivery
Draft ~2 weeks after fieldwork
You receive a polished draft reviewed for consistency, accuracy, and clarity, with the final report issued within 5 to 7 weeks of period end. We debrief on findings and coordinate with your clients' auditors as needed.
Ongoing Support
Year-round
We stay involved after report delivery, helping with auditor questions, control updates, and keeping you ready for the next audit cycle.
We specialize in systems, infrastructure, and technology. We are a firm built intentionally small so that standard never slips.

Jordan Novak
Managing Partner

Tasya Novak
Managing Director
We don't scale by adding junior staff to your engagement. We stay involved because that's the only way to consistently deliver work worth standing behind. Meet the team.
We use modern tools to streamline evidence collection and reduce back-and-forth. Faster timelines, fewer disruptions. See how we avoid audit pain points.
No two audits run the same way because no two environments are the same. Learn about our process.
Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.
Real numbers, a real conversation with a qualified CPA. No obligation.
Why Sage Audits
Sage Audits is a licensed Colorado CPA firm and AICPA member serving SaaS and B2B technology companies nationwide.
Get a Fixed-Fee QuotePeople
A partner runs your engagement from scoping through report delivery, and the person signing the opinion is the person you talk to.
Pricing
One fixed fee, quoted before work begins, with no hourly meters.
Platform
Vanta, Drata, Secureframe, or spreadsheets: we start from the evidence you already have and build from there.
Timeline
Draft report within 2 weeks of fieldwork completion and the final report within 5 to 7 weeks of period end.
Answers to the questions we hear most often from CTOs, VPs of Engineering, and compliance leads evaluating SOC 2 for the first time.
Talk to a PartnerA SOC 2 Type I typically takes approximately one to two months from kickoff to report issuance, assuming controls are in place. A SOC 2 Type II depends on your examination period (6 to 12 months), with a draft report within two weeks of fieldwork completion and the final report within five to seven weeks of period end.
For a first-time engagement, total timeline from kickoff to final report is typically 8 to 16 months depending on how much remediation you need and your audit period length. Renewals run shorter because the readiness work falls away.
SOC 2 pricing is driven by the report type, the Trust Services Categories in scope, and the size and complexity of your environment, so a meaningful number requires scoping rather than a rate card. Directionally: a readiness assessment costs less than an audit, a Type I costs less than a Type II, and every category you add beyond Security expands testing and cost. We frequently offer package pricing when readiness, Type I, and Type II work are engaged together.
We provide a fixed-fee proposal scoped to your actual environment, so there are no billing surprises. Use our pricing calculator for an estimate, or request a quote →
No. A Type I is not a prerequisite for a Type II. Many organizations go directly to a Type II, especially if they have strong controls in place. A Type I is most useful when you need a report quickly to satisfy a customer requirement while your Type II audit period runs concurrently.
Security (CC criteria) is required in every SOC 2 Report. Additional categories, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and selected based on your service commitments and what your customers care about.
Most companies start with Security only; Confidentiality is the most common addition, and Availability comes next, especially for SaaS. We help you determine the right scope during our initial scoping call so you are not over- or under-audited. Read our breakdown of all five categories.
Yes. We work directly within your GRC platform throughout the engagement. We pull evidence from Vanta, Drata, Secureframe, TrustCloud, and similar tools, and we will tell you exactly what evidence format we need so collection is as lightweight as possible. Using a GRC platform does not reduce audit rigor, it reduces the manual burden on your team.
That is exactly what a readiness assessment is for. We identify gaps before your audit period begins so you have time to remediate. Discovering gaps during the audit is far more disruptive and costly. Our readiness engagements are structured to give you a clear, prioritized action list, not a generic checklist.
You work directly with a partner from scoping call through final report delivery. We do not hand off engagements to junior staff after the kickoff. The partner who scopes your engagement leads fieldwork, reviews findings, and signs the report.
With preparation, fieldwork is a concentrated 3 to 4 week window. The most common pain point is evidence collection, which GRC platforms significantly reduce. We provide a detailed evidence request list upfront, with clear format requirements, so your team is not fielding unclear back-and-forth requests during the audit.
A SOC 2 Report contains: management's description of the system, including boundaries and service commitments; the auditor's opinion letter; a description of tests performed and the results; and, for Type II, a summary of any exceptions or noted deviations.
The report is confidential and shared only with customers and stakeholders under NDA. It is not a public certification, though many companies note their SOC 2 status publicly.
SOC 2 covers overlapping control domains with ISO 27001 and HIPAA. Many of the controls you implement for SOC 2 directly support HIPAA Security Rule compliance or ISO 27001 certification. Today we map SOC 2 control environments to NIST CSF and SOX ITGC within the same engagement; ISO 27001 and HIPAA mappings are on our roadmap and can be scoped by amendment, giving your customers and partners a broader view of your compliance posture without doubling your audit effort.
SOC 2 Type II reports are issued for a specific audit period and typically renewed annually. Most enterprise customers and vendor security questionnaires expect a report dated within the last 12 months. Annual renewals are generally faster and more efficient than the initial engagement because the foundational documentation and scoping work is already in place.
If you are losing deals because enterprise procurement is asking for a SOC 2 Report, it is not too early. We work with early-stage companies regularly, and the readiness phase is designed to meet you where you are, not assume you have a mature compliance program in place.
The right time to start is when it is costing you customers or adding friction to your sales process.
Perspectives